View Full Version : Is this a virus?
buddytod
05-09-2003, 06:29 AM
Put together a new system 2 weeks ago...Abit KD7 Mobo, Athlon xp2.4, 512mb pc2700 mem, 2 * 80gb hdd, Geforce Ti 4200 graphics, SB Audigy etc.
OS at the time was ME. Loaded well used previously reliable software, e.g smartripper, Kazaa + games including Battlefield 1942. After a couple of days I found that some programs would not start. Messages like...File was altered or 'This program has performed.... etc etc. Battlefield 1942 suddenly refused to start at all (hourglass for 2 seconds then nothing...no messages or crashes. The only option with these programs is to reinstall them. They work fine for a day or 2(sometimes an hour or 2)! then it happens again. There are 3 other computers in our home(Kids) & they are all networked. My sons computer also began refusing Battlefield at the same time and continues to display the same problems that I have. I should point out that there are many other games and applications that do not give any problems. We have had our pc's networked for approx 2 years using pretty much the same software with no problems at all. I have formatted all the drives on all pc's, loaded xp on all and still the same programs are suddenly ceasing to work without any explanation. I have built all our pc's for the past 5 years, installed the os and configured the hardware and never have I come across a situation like this! Help would be greatly appreciated
YODA74
05-09-2003, 06:51 AM
go here get Highjackthis,run it also "startup list" run it post your results.While your there get "Kazaa be gone" and get that nonsence off your computer. http://www.spywareinfo.com/~merijn/index.html
Also get spybot here http://security.kolla.de/
jabarnutcase
05-09-2003, 07:49 AM
Loaded well used previously reliable software, e.g smartripper, Kazaa + games ......
Yoda speaks the truth....Kazza is one of the worst pieces of junk out there for spyware and god knows what else depending on what you download and from who.
I'm sure when just about anyone here see's the name "KaZaa, they think...:eek:
Run YODA'S suggested programs...And getting completely rid of Kazaa won't be easy.
Hopefully, you do have an updated Anti-virus program and have also run a scan with that.
Just ridding your computer of spyware will cause Kazaa to cease to function....That should tell you something. Good luck! ;)
To completely remove Kazza there is a utility avaiable from the maker of HijackThis called Kazaabegone.
buddytod
05-09-2003, 11:21 AM
O.K..............Have run the 2 suggested utilitys and no problems shown up. Yes, I appreciate fully what has been said regarding Kazaa(You can actually run it with a 'dummy' clint.dll file which knocks out any adware etc but that's by the by).
I will remove this software but I am no wiser as to what is causing the problems I have outlined. Since most of my system is new could it be a Memory/hdd related problem? As I said, 95% of my software is running perfectly, but the progs that are causing the probs are ones that I have had installed on various machines for 2 years or more with no problems before. I can live without these but if there is a problem it may well occur in programs I CANNOT do without. Can you suggest which Virus checking software & memory checker I should purchase? I feel I should mention once again that all these probs started with this new machine and have existed in win ME and, following a partition removal with fdisk and format have continued under wim XP exactly the same!
Budfred
05-09-2003, 11:27 AM
Check mjc's sig for a link to his thread for AV and other security software. If you are not currently running an AV and you are running Kazaa, you probably have a virus and/or other crap in your network. You may be able to block some of the crap from Kazaa, but not all of it...
Many people around here like AVG for free AV software. I would also urge you to download and run Spybot and/or AdAware to deal with spyware and I would urge you to run Hijack This and post the logs as suggested. You may have a massive cleanup to do, but it is hard to say what until you post the logs.
buddytod
05-09-2003, 02:55 PM
Here are the results of 'Hijack This'
Logfile v1.94.0
Scan saved at 19:16:21, on 09/05/03
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v5.50 (5.50.4134.0600)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://www.aol.co.uk/search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.aol.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL=http://www.aol.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title=Microsoft Internet Explorer provided by AOL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - Startup: AOL 7.0 Tray Icon.lnk = C:\Program Files\AOL 7.0\aoltray.exe
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O14 - IERESET.INF: START_PAGE_URL=http://www.aol.co.ukStartupList report, 09/05/03, 19:59:52
Startup list
StartupList version: 1.52
Started from : C:\WINDOWS\TEMP\RAR$EX0D.3TL\STARTUPLIST.EXE
Detected: Windows 98 Gold (Win9x 4.10.1998)
Detected: Internet Explorer v5.50 (5.50.4134.0600)
* Using default options
==================================================
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\WINDOWS\RunDLL.exe
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\AOL 7.0\WAOL.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\WINRAR\WINRAR.EXE
C:\WINDOWS\TEMP\RAR$EX0D.3TL\STARTUPLIST.EXE
--------------------------------------------------
Listing of startup folders:
Shell folders Startup:
[C:\WINDOWS\Start Menu\Programs\StartUp]
AOL 7.0 Tray Icon.lnk = C:\Program Files\AOL 7.0\aoltray.exe
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
TaskMonitor = C:\WINDOWS\taskmon.exe
SystemTray = SysTray.Exe
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup
nwiz = nwiz.exe /install
RealTray = C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run Services
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
SchedulingAgent = mstask.exe
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Taskbar Display Controls = RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
--------------------------------------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=Explorer.exe
SCRNSAVE.EXE=
drivers=mmsystem.dll power.drv
--------------------------------------------------
C:\WINDOWS\WININIT.INI listing:
(Created 9/5/2003, 19:37:20)
[rename]
NUL=C:\WINDOWS\TEMP\_iu14D2N.tmp
--------------------------------------------------
C:\WINDOWS\WININIT.BAK listing:
(Created 9/5/2003, 17:52:14)
[rename]
NUL=C:\WINDOWS\TEMP\_iu14D2N.tmp
NUL=C:\WINDOWS\TEMP\GLB1A2B.EXE
NUL=C:\PROGRA~1\ZONELA~1\ZONEAL~1\ZAUNINST.EXE
--------------------------------------------------
C:\AUTOEXEC.BAT listing:
mode con codepage prepare=((850) C:\WINDOWS\COMMAND\ega.cpi)
mode con codepage select=850
keyb uk,,C:\WINDOWS\COMMAND\keyboard.sys
--------------------------------------------------
Enumerating Task Scheduler jobs:
Tune-up Application Start.job
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
WebCheck: C:\WINDOWS\SYSTEM\WEBCHECK.DLL
--------------------------------------------------
End of report, 3,861 bytes
Report generated in 0.074 seconds
pentachris
05-09-2003, 03:15 PM
I'm not the most experienced person to be reading your log, but everything looks fairly clean to me. Except I wouldn't want realplayer loading with windows, but that's not a big deal.
pentachris
05-10-2003, 02:31 AM
I'm not the most experienced person to be reading your log
Um... That's your cue to jump in here, mjc, rick, ghosthacker, etc...
gwallen4
05-11-2003, 10:26 PM
Could be a memory problem. Check this first with one of the memory checkers.
Are you overclocking? Overclocking with the wrong ratios (FSB/AGP/PCI) can result in hard disk errors or corruption.
Log looks squeeky clean....other than a couple of performance issues.
Quickres is nice but it often eats 2 to 4% system resources, same goes for Scheduling Agent.
Real Player can be shut off too...
buddytod
05-12-2003, 05:40 AM
I,m Back............After yet another Fdisk/Format & Reinstall!
I tried AVG and....it moved approx 75% of my entire files to the Quarantene folder! I cannot remember the exact problem except that it related to win 32...and every file was reported with the same problem.
I went and purchased McAfee Virus Scan, Fdisked/Format and just loaded windows with the mobo and graphic card drivers. I then installed McAfee and following a scan of drive c, reported 13 contaminated files. The 'worm' in question was W32/PATE.b. This is apparently a 177kb file which attatches itself to .exe files. Origin unknown.
The strange thing is that the only software I installed up to that point was from cd's i.e Windows/Mobo drivers and Graphics driver cd. Boot up floppy reported clean. I cleaned the 13 files and touch wood everything so far seems ok.....BUT I have to admit that I am far from confident! I would be happier if I could have found the source but there is certainly nothing on my install software.(I have actually scanned 114,000 files from my back up cd's, including the Kazaa install prog!!! and......nothing! As you noticed, my startup files etc seemed ok but I was still having major problems with some files. I have reloaded the relevant files and at the moment they are performing perfectly. I take on board what was mentiond about the Memory and systen config. Thanks everyone for the advice....I'll keep you posted!!
vBulletin v3.6.1, Copyright ©2000-2012, Jelsoft Enterprises Ltd.